Credential access
Reads auth.json, repository tokens, environment variables, and project config.
brew / rank 315
Dependency Manager for PHP. Version 2.10.2 via Homebrew; verified 2026-07-01.
agent safety
composer manages PHP dependencies and package publishing workflows.
Reads auth.json, repository tokens, environment variables, and project config.
Can install packages and run scripts that affect remote systems.
Can publish packages or build deployable PHP artifacts.
Gate scripts, publish operations, and credentialed repository access.
Allow dependency inspection; require approval for scripts, publishes, and private-repo credentials.
install
brew install composerprovider-native install command
overview
Dependency Manager for PHP
history
Composer is the standard dependency manager for PHP projects. It lets projects declare library dependencies, resolves installable versions, and installs packages into the project rather than acting like a system package manager.
Composer was created by Nils Adermann and Jordi Boggiano and released under the MIT license. Official documentation describes it as inspired by npm and Bundler, bringing per-project dependency resolution and installation to PHP. Packagist serves as the public package index for Composer packages.
Packagist records `composer/composer` package versions starting with 1.0.0-alpha1 in 2012, and GitHub releases include 1.0.0-alpha1 in 2013. The official README points users to Packagist for public packages and to Private Packagist for private hosting, showing how Composer became both a CLI and a package ecosystem.
Normal Composer usage starts with a project `composer.json`, produces a lock file for reproducible installs, and installs dependencies into `vendor`. It can be installed locally as a PHAR, globally on PATH, through Docker, or through OS package managers such as Homebrew.
Composer is package-manager infrastructure, not just a CLI. Its resolver, lock file, Packagist integration, authentication model, and VCS support made PHP packages installable with dependency constraints in a way familiar to users of npm, Bundler, and other language package managers.
security posture
infrastructure mutation or orchestration signal.
orange risk · medium confidence · infrastructure
Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.
local files
These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.
Credential-bearing paths to review before unattended agent runs.
~/Library/Application Support/Composer/auth.json$XDG_CONFIG_HOME/composer/auth.json~/.composer/auth.jsonexecutables
| Command | Kind | Exposure | Note |
|---|---|---|---|
composer | executable | indexed executable | Discovered from the local executable index. |
freshness
These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.
install metadata
| Package key | brew:composer |
|---|---|
| Version | 2.10.2 |
| Package manager | Homebrew |
| Homepage | https://getcomposer.org/ |
| Last updated | 2026-07-01T13:09:12Z |
| Pulse | updated |
| Bottle | not recorded |
| Service | none declared |
source trail
This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.
View the package source record on GitHub.